diff --git a/advisories/unreviewed/2022/05/GHSA-w2rw-pv8p-h9c8/GHSA-w2rw-pv8p-h9c8.json b/advisories/unreviewed/2022/05/GHSA-w2rw-pv8p-h9c8/GHSA-w2rw-pv8p-h9c8.json index f7557f52779..1b4f296a695 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2rw-pv8p-h9c8/GHSA-w2rw-pv8p-h9c8.json +++ b/advisories/unreviewed/2022/05/GHSA-w2rw-pv8p-h9c8/GHSA-w2rw-pv8p-h9c8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w2rw-pv8p-h9c8", - "modified": "2022-05-13T01:05:08Z", + "modified": "2025-03-31T15:30:38Z", "published": "2022-05-13T01:05:08Z", "aliases": [ "CVE-2016-2183" @@ -25,7 +25,11 @@ }, { "type": "WEB", - "url": "https://www.teskalabs.com/blog/teskalabs-bulletin-160826-seacat-sweet32-issue" + "url": "https://support.f5.com/csp/article/K13167034" + }, + { + "type": "WEB", + "url": "https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03286178" }, { "type": "WEB", @@ -101,7 +105,15 @@ }, { "type": "WEB", - "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680" + "url": "https://www.vicarius.io/vsociety/posts/cve-2016-2183-mitigate-sweet32-vulnerability" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2016-2183-detection-sweet32-vulnerability" + }, + { + "type": "WEB", + "url": "https://www.teskalabs.com/blog/teskalabs-bulletin-160826-seacat-sweet32-issue" }, { "type": "WEB", @@ -181,11 +193,7 @@ }, { "type": "WEB", - "url": "https://support.f5.com/csp/article/K13167034" - }, - { - "type": "WEB", - "url": "https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03286178" + "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680" }, { "type": "WEB", diff --git a/advisories/unreviewed/2022/08/GHSA-r2vv-rr99-h5p9/GHSA-r2vv-rr99-h5p9.json b/advisories/unreviewed/2022/08/GHSA-r2vv-rr99-h5p9/GHSA-r2vv-rr99-h5p9.json index 8e52fab8142..74e5478b293 100644 --- a/advisories/unreviewed/2022/08/GHSA-r2vv-rr99-h5p9/GHSA-r2vv-rr99-h5p9.json +++ b/advisories/unreviewed/2022/08/GHSA-r2vv-rr99-h5p9/GHSA-r2vv-rr99-h5p9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r2vv-rr99-h5p9", - "modified": "2022-08-19T00:00:20Z", + "modified": "2025-03-31T15:30:35Z", "published": "2022-08-19T00:00:20Z", "aliases": [ "CVE-2022-37061" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://gist.github.com/Nwqda/9e16852ab7827dc62b8e44d6180a6899" }, + { + "type": "WEB", + "url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2022-36266/FLIR%20AX8%20Unauthenticated%20OS%20Command%20Injection.py" + }, { "type": "WEB", "url": "https://www.flir.com/products/ax8-automation" diff --git a/advisories/unreviewed/2023/01/GHSA-65rh-7mcj-934p/GHSA-65rh-7mcj-934p.json b/advisories/unreviewed/2023/01/GHSA-65rh-7mcj-934p/GHSA-65rh-7mcj-934p.json index d1f7cb96e6f..add9a3021eb 100644 --- a/advisories/unreviewed/2023/01/GHSA-65rh-7mcj-934p/GHSA-65rh-7mcj-934p.json +++ b/advisories/unreviewed/2023/01/GHSA-65rh-7mcj-934p/GHSA-65rh-7mcj-934p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65rh-7mcj-934p", - "modified": "2023-02-01T18:30:24Z", + "modified": "2025-03-31T15:30:36Z", "published": "2023-01-26T21:30:20Z", "aliases": [ "CVE-2023-0394" diff --git a/advisories/unreviewed/2025/03/GHSA-29w3-4r4c-4fmm/GHSA-29w3-4r4c-4fmm.json b/advisories/unreviewed/2025/03/GHSA-29w3-4r4c-4fmm/GHSA-29w3-4r4c-4fmm.json new file mode 100644 index 00000000000..490e364a592 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-29w3-4r4c-4fmm/GHSA-29w3-4r4c-4fmm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29w3-4r4c-4fmm", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-22940" + ], + "details": "Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22940" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2pj3-3r8x-phjq/GHSA-2pj3-3r8x-phjq.json b/advisories/unreviewed/2025/03/GHSA-2pj3-3r8x-phjq/GHSA-2pj3-3r8x-phjq.json index a50694baf35..d8b345ae8ca 100644 --- a/advisories/unreviewed/2025/03/GHSA-2pj3-3r8x-phjq/GHSA-2pj3-3r8x-phjq.json +++ b/advisories/unreviewed/2025/03/GHSA-2pj3-3r8x-phjq/GHSA-2pj3-3r8x-phjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pj3-3r8x-phjq", - "modified": "2025-03-31T12:30:46Z", + "modified": "2025-03-31T15:30:44Z", "published": "2025-03-31T12:30:45Z", "aliases": [ "CVE-2025-2994" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2994" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-qossetting-1bc53a41781f80a2aa2fde152bf948b5" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-qossetting-1bc53a41781f80a2aa2fde152bf948b5?pvs=4" diff --git a/advisories/unreviewed/2025/03/GHSA-2rqj-34g2-6fp3/GHSA-2rqj-34g2-6fp3.json b/advisories/unreviewed/2025/03/GHSA-2rqj-34g2-6fp3/GHSA-2rqj-34g2-6fp3.json new file mode 100644 index 00000000000..107346d10a4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2rqj-34g2-6fp3/GHSA-2rqj-34g2-6fp3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rqj-34g2-6fp3", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31601" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in appointy Appointy Appointment Scheduler allows Cross Site Request Forgery. This issue affects Appointy Appointment Scheduler: from n/a through 4.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31601" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appointy-appointment-scheduler/vulnerability/wordpress-appointy-appointment-scheduler-plugin-4-2-1-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-35fx-xjv3-96x2/GHSA-35fx-xjv3-96x2.json b/advisories/unreviewed/2025/03/GHSA-35fx-xjv3-96x2/GHSA-35fx-xjv3-96x2.json new file mode 100644 index 00000000000..a7859d72376 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-35fx-xjv3-96x2/GHSA-35fx-xjv3-96x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35fx-xjv3-96x2", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31611" + ], + "details": "Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Post After Image Upload: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31611" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/auto-post-after-image-upload/vulnerability/wordpress-auto-post-after-image-upload-plugin-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3857-jq6x-m933/GHSA-3857-jq6x-m933.json b/advisories/unreviewed/2025/03/GHSA-3857-jq6x-m933/GHSA-3857-jq6x-m933.json new file mode 100644 index 00000000000..f29f969af44 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3857-jq6x-m933/GHSA-3857-jq6x-m933.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3857-jq6x-m933", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31621" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidpaulsson byBrick Accordion allows Stored XSS. This issue affects byBrick Accordion: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31621" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bybrick-accordion/vulnerability/wordpress-bybrick-accordion-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3899-g6fw-rr82/GHSA-3899-g6fw-rr82.json b/advisories/unreviewed/2025/03/GHSA-3899-g6fw-rr82/GHSA-3899-g6fw-rr82.json new file mode 100644 index 00000000000..f960ac25ba2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3899-g6fw-rr82/GHSA-3899-g6fw-rr82.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3899-g6fw-rr82", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31625" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ramanparashar Useinfluence allows Stored XSS. This issue affects Useinfluence: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31625" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/useinfluence/vulnerability/wordpress-useinfluence-plugin-1-0-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3gqf-jg6j-f9gc/GHSA-3gqf-jg6j-f9gc.json b/advisories/unreviewed/2025/03/GHSA-3gqf-jg6j-f9gc/GHSA-3gqf-jg6j-f9gc.json new file mode 100644 index 00000000000..67c8a464c6f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3gqf-jg6j-f9gc/GHSA-3gqf-jg6j-f9gc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gqf-jg6j-f9gc", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31602" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in apimofficiel Apimo Connector allows Cross Site Request Forgery. This issue affects Apimo Connector: from n/a through 2.6.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31602" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apimo/vulnerability/wordpress-apimo-connector-plugin-2-6-3-1-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3m95-wfxh-25xv/GHSA-3m95-wfxh-25xv.json b/advisories/unreviewed/2025/03/GHSA-3m95-wfxh-25xv/GHSA-3m95-wfxh-25xv.json new file mode 100644 index 00000000000..a5ba1da0d8a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3m95-wfxh-25xv/GHSA-3m95-wfxh-25xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m95-wfxh-25xv", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31539" + ], + "details": "Missing Authorization vulnerability in Blocksera Cryptocurrency Widgets Pack allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cryptocurrency Widgets Pack: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31539" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cryptocurrency-widgets-pack/vulnerability/wordpress-cryptocurrency-widgets-pack-plugin-2-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3rq3-6pw2-f97f/GHSA-3rq3-6pw2-f97f.json b/advisories/unreviewed/2025/03/GHSA-3rq3-6pw2-f97f/GHSA-3rq3-6pw2-f97f.json new file mode 100644 index 00000000000..d8a32b4b41e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3rq3-6pw2-f97f/GHSA-3rq3-6pw2-f97f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rq3-6pw2-f97f", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2023-33302" + ], + "details": "A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33302" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-21-023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-429p-hfv2-984f/GHSA-429p-hfv2-984f.json b/advisories/unreviewed/2025/03/GHSA-429p-hfv2-984f/GHSA-429p-hfv2-984f.json new file mode 100644 index 00000000000..5fb42685f8d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-429p-hfv2-984f/GHSA-429p-hfv2-984f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-429p-hfv2-984f", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-22938" + ], + "details": "Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22938" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-42m2-24p7-q2gq/GHSA-42m2-24p7-q2gq.json b/advisories/unreviewed/2025/03/GHSA-42m2-24p7-q2gq/GHSA-42m2-24p7-q2gq.json new file mode 100644 index 00000000000..9f25cc53f08 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-42m2-24p7-q2gq/GHSA-42m2-24p7-q2gq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42m2-24p7-q2gq", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31566" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery allows Stored XSS. This issue affects Rio Video Gallery: from n/a through 2.3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31566" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rio-video-gallery/vulnerability/wordpress-rio-video-gallery-plugin-2-3-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-44jr-xc7x-rpwx/GHSA-44jr-xc7x-rpwx.json b/advisories/unreviewed/2025/03/GHSA-44jr-xc7x-rpwx/GHSA-44jr-xc7x-rpwx.json new file mode 100644 index 00000000000..9c7bfbbc091 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-44jr-xc7x-rpwx/GHSA-44jr-xc7x-rpwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44jr-xc7x-rpwx", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31545" + ], + "details": "Missing Authorization vulnerability in WP Messiah Safe Ai Malware Protection for WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Safe Ai Malware Protection for WP: from n/a through 1.0.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31545" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/safe-ai-malware-protection-for-wp/vulnerability/wordpress-safe-ai-malware-protection-for-wp-plugin-1-0-20-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4hjc-7286-ffp5/GHSA-4hjc-7286-ffp5.json b/advisories/unreviewed/2025/03/GHSA-4hjc-7286-ffp5/GHSA-4hjc-7286-ffp5.json new file mode 100644 index 00000000000..435759ced22 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4hjc-7286-ffp5/GHSA-4hjc-7286-ffp5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hjc-7286-ffp5", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31588" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in elfsight Elfsight Testimonials Slider allows Cross Site Request Forgery. This issue affects Elfsight Testimonials Slider: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31588" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elfsight-testimonials-slider/vulnerability/wordpress-elfsight-testimonials-slider-plugin-1-0-1-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-59pj-2g8h-96c8/GHSA-59pj-2g8h-96c8.json b/advisories/unreviewed/2025/03/GHSA-59pj-2g8h-96c8/GHSA-59pj-2g8h-96c8.json new file mode 100644 index 00000000000..d6c5d467d27 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-59pj-2g8h-96c8/GHSA-59pj-2g8h-96c8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59pj-2g8h-96c8", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31572" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in v20202020 Multi Days Events and Multi Events in One Day Calendar allows Cross Site Request Forgery. This issue affects Multi Days Events and Multi Events in One Day Calendar: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31572" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dragon-calendar-free-version/vulnerability/wordpress-multi-days-events-and-multi-events-in-one-day-calendar-plugin-1-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-624x-gfg4-2hqg/GHSA-624x-gfg4-2hqg.json b/advisories/unreviewed/2025/03/GHSA-624x-gfg4-2hqg/GHSA-624x-gfg4-2hqg.json new file mode 100644 index 00000000000..1bb9761e5ab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-624x-gfg4-2hqg/GHSA-624x-gfg4-2hqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-624x-gfg4-2hqg", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31614" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hiroprot Terms Before Download allows Stored XSS. This issue affects Terms Before Download: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31614" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/terms-before-download/vulnerability/wordpress-terms-before-download-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6478-c8g6-qg4r/GHSA-6478-c8g6-qg4r.json b/advisories/unreviewed/2025/03/GHSA-6478-c8g6-qg4r/GHSA-6478-c8g6-qg4r.json new file mode 100644 index 00000000000..42524db4100 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6478-c8g6-qg4r/GHSA-6478-c8g6-qg4r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6478-c8g6-qg4r", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31620" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in carperfer CoverManager allows Stored XSS. This issue affects CoverManager: from n/a through 0.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31620" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/covermanager/vulnerability/wordpress-covermanager-plugin-0-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-68gm-jhfr-59cm/GHSA-68gm-jhfr-59cm.json b/advisories/unreviewed/2025/03/GHSA-68gm-jhfr-59cm/GHSA-68gm-jhfr-59cm.json new file mode 100644 index 00000000000..6a7ab0071a8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-68gm-jhfr-59cm/GHSA-68gm-jhfr-59cm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68gm-jhfr-59cm", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31586" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery – Photo Albums Plugin allows Stored XSS. This issue affects Gallery – Photo Albums Plugin: from n/a through 1.3.170.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31586" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-media-gallery/vulnerability/wordpress-gallery-photo-albums-plugin-plugin-1-3-170-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-68wx-jp22-pw7g/GHSA-68wx-jp22-pw7g.json b/advisories/unreviewed/2025/03/GHSA-68wx-jp22-pw7g/GHSA-68wx-jp22-pw7g.json new file mode 100644 index 00000000000..ec21e2b43ec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-68wx-jp22-pw7g/GHSA-68wx-jp22-pw7g.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68wx-jp22-pw7g", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-2995" + ], + "details": "A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulnerability affects unknown code of the file /goform/SysToolChangePwd of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2995" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-SysToolChangePwd-1bc53a41781f809b95a4efb617090d3c" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-SysToolChangePwd-1bc53a41781f809b95a4efb617090d3c?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302044" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302044" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.523418" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-69r2-xm85-6fhr/GHSA-69r2-xm85-6fhr.json b/advisories/unreviewed/2025/03/GHSA-69r2-xm85-6fhr/GHSA-69r2-xm85-6fhr.json new file mode 100644 index 00000000000..56b6e05809b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-69r2-xm85-6fhr/GHSA-69r2-xm85-6fhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69r2-xm85-6fhr", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31562" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aphotrax Uptime Robot Plugin for WordPress allows DOM-Based XSS. This issue affects Uptime Robot Plugin for WordPress: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31562" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uptime-robot-monitor/vulnerability/wordpress-uptime-robot-plugin-for-wordpress-plugin-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6jff-r82g-f2wj/GHSA-6jff-r82g-f2wj.json b/advisories/unreviewed/2025/03/GHSA-6jff-r82g-f2wj/GHSA-6jff-r82g-f2wj.json new file mode 100644 index 00000000000..3ffb76004d1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6jff-r82g-f2wj/GHSA-6jff-r82g-f2wj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jff-r82g-f2wj", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31603" + ], + "details": "Missing Authorization vulnerability in moshensky CF7 Spreadsheets allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 Spreadsheets: from n/a through 2.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31603" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-spreadsheets/vulnerability/wordpress-cf7-spreadsheets-plugin-2-3-2-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6p8v-9ccm-58gj/GHSA-6p8v-9ccm-58gj.json b/advisories/unreviewed/2025/03/GHSA-6p8v-9ccm-58gj/GHSA-6p8v-9ccm-58gj.json new file mode 100644 index 00000000000..4ac2c1f3694 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6p8v-9ccm-58gj/GHSA-6p8v-9ccm-58gj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p8v-9ccm-58gj", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31585" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in leadfox Leadfox for WordPress allows Cross Site Request Forgery. This issue affects Leadfox for WordPress: from n/a through 2.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31585" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leadfox/vulnerability/wordpress-leadfox-for-wordpress-plugin-2-1-8-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6q96-cqf2-7rw3/GHSA-6q96-cqf2-7rw3.json b/advisories/unreviewed/2025/03/GHSA-6q96-cqf2-7rw3/GHSA-6q96-cqf2-7rw3.json new file mode 100644 index 00000000000..b90a4772af6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6q96-cqf2-7rw3/GHSA-6q96-cqf2-7rw3.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q96-cqf2-7rw3", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-2997" + ], + "details": "A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown function of the file /res/url. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2997" + }, + { + "type": "WEB", + "url": "https://github.com/exp3n5ive/Vul/blob/main/youkefu/youkefu.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302046" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302046" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7cqm-hpmj-xq4h/GHSA-7cqm-hpmj-xq4h.json b/advisories/unreviewed/2025/03/GHSA-7cqm-hpmj-xq4h/GHSA-7cqm-hpmj-xq4h.json new file mode 100644 index 00000000000..49cfffce378 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7cqm-hpmj-xq4h/GHSA-7cqm-hpmj-xq4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cqm-hpmj-xq4h", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31546" + ], + "details": "Missing Authorization vulnerability in WP Messiah Swiss Toolkit For WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Swiss Toolkit For WP: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31546" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/swiss-toolkit-for-wp/vulnerability/wordpress-swiss-toolkit-for-wp-plugin-1-3-0-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7cvr-2mm5-4w4w/GHSA-7cvr-2mm5-4w4w.json b/advisories/unreviewed/2025/03/GHSA-7cvr-2mm5-4w4w/GHSA-7cvr-2mm5-4w4w.json new file mode 100644 index 00000000000..34465d07297 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7cvr-2mm5-4w4w/GHSA-7cvr-2mm5-4w4w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cvr-2mm5-4w4w", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31532" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team AtomChat AtomChat allows Stored XSS. This issue affects AtomChat: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31532" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/atomchat/vulnerability/wordpress-atomchat-plugin-1-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7v43-7xp7-5hx7/GHSA-7v43-7xp7-5hx7.json b/advisories/unreviewed/2025/03/GHSA-7v43-7xp7-5hx7/GHSA-7v43-7xp7-5hx7.json new file mode 100644 index 00000000000..365d48c2e87 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7v43-7xp7-5hx7/GHSA-7v43-7xp7-5hx7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v43-7xp7-5hx7", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31526" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager allows SQL Injection. This issue affects Behance Portfolio Manager: from n/a through 1.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31526" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/portfolio-manager-powered-by-behance/vulnerability/wordpress-behance-portfolio-manager-plugin-1-7-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7wr7-jjqm-jqvv/GHSA-7wr7-jjqm-jqvv.json b/advisories/unreviewed/2025/03/GHSA-7wr7-jjqm-jqvv/GHSA-7wr7-jjqm-jqvv.json new file mode 100644 index 00000000000..a086b965fc5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7wr7-jjqm-jqvv/GHSA-7wr7-jjqm-jqvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wr7-jjqm-jqvv", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31617" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Gagan Deep Singh PostmarkApp Email Integrator allows Cross Site Request Forgery. This issue affects PostmarkApp Email Integrator: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31617" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/postmarkapp-email-integrator/vulnerability/wordpress-postmarkapp-email-integrator-plugin-2-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7xwr-85xj-7jqw/GHSA-7xwr-85xj-7jqw.json b/advisories/unreviewed/2025/03/GHSA-7xwr-85xj-7jqw/GHSA-7xwr-85xj-7jqw.json new file mode 100644 index 00000000000..983429c54b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7xwr-85xj-7jqw/GHSA-7xwr-85xj-7jqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xwr-85xj-7jqw", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31535" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple Owl Carousel allows DOM-Based XSS. This issue affects Simple Owl Carousel: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31535" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-owl-carousel/vulnerability/wordpress-simple-owl-carousel-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-889c-695c-6qf9/GHSA-889c-695c-6qf9.json b/advisories/unreviewed/2025/03/GHSA-889c-695c-6qf9/GHSA-889c-695c-6qf9.json new file mode 100644 index 00000000000..8a254118aea --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-889c-695c-6qf9/GHSA-889c-695c-6qf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-889c-695c-6qf9", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31595" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History allows Stored XSS. This issue affects Timeline Event History: from n/a through 3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31595" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/timeline-event-history/vulnerability/wordpress-timeline-event-history-plugin-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-89jg-hp5v-8qq9/GHSA-89jg-hp5v-8qq9.json b/advisories/unreviewed/2025/03/GHSA-89jg-hp5v-8qq9/GHSA-89jg-hp5v-8qq9.json new file mode 100644 index 00000000000..568e7dfc688 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-89jg-hp5v-8qq9/GHSA-89jg-hp5v-8qq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89jg-hp5v-8qq9", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31587" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Testimonials Slider allows Stored XSS. This issue affects Elfsight Testimonials Slider: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31587" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elfsight-testimonials-slider/vulnerability/wordpress-elfsight-testimonials-slider-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-89m6-xgf5-h8qg/GHSA-89m6-xgf5-h8qg.json b/advisories/unreviewed/2025/03/GHSA-89m6-xgf5-h8qg/GHSA-89m6-xgf5-h8qg.json new file mode 100644 index 00000000000..a13f186227a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-89m6-xgf5-h8qg/GHSA-89m6-xgf5-h8qg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89m6-xgf5-h8qg", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31549" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion allows DOM-Based XSS. This issue affects Fusion: from n/a through 1.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31549" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fusion/vulnerability/wordpress-fusion-plugin-1-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8rwh-379g-4x2r/GHSA-8rwh-379g-4x2r.json b/advisories/unreviewed/2025/03/GHSA-8rwh-379g-4x2r/GHSA-8rwh-379g-4x2r.json new file mode 100644 index 00000000000..0f88767e269 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8rwh-379g-4x2r/GHSA-8rwh-379g-4x2r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rwh-379g-4x2r", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-2996" + ], + "details": "A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. This issue affects some unknown processing of the file /goform/SysToolDDNS of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2996" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-SysToolDDNS-1bc53a41781f8012a03be8bebed1125b?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302045" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302045" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.523419" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8vh6-m67f-4h33/GHSA-8vh6-m67f-4h33.json b/advisories/unreviewed/2025/03/GHSA-8vh6-m67f-4h33/GHSA-8vh6-m67f-4h33.json new file mode 100644 index 00000000000..fa1ec68257b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8vh6-m67f-4h33/GHSA-8vh6-m67f-4h33.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vh6-m67f-4h33", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-30095" + ], + "details": "VyOS 1.3 through 1.5 or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. I n VyOS, this is not the default configuration for the system SSH daemon, but is for the console service. To mitigate this, one can run \"rm -f /etc/dropbear/*key*\" and/or \"rm -f /etc/dropbear-initramfs/*key*\" and then dropbearkey -t rsa -s 4096 -f /etc/dropbear_rsa_host_key and reload the service or reboot the system before using Dropbear as the SSH daemon (this clears out all keys mistakenly built into the release image) or update to the latest version of VyOS 1.4 or 1.5. Note that this vulnerability is not unique to VyOS and may appear in any Debian-based Linux distribution that uses Dropbear in combination with live-build, which has a safeguard against this behavior in OpenSSH but no equivalent one for Dropbear.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30095" + }, + { + "type": "WEB", + "url": "https://blog.vyos.io/vyos-project-march-2025-update" + }, + { + "type": "WEB", + "url": "https://blog.vyos.io/vyos-stream-1.5-2025-q1" + }, + { + "type": "WEB", + "url": "https://github.com/vyos" + }, + { + "type": "WEB", + "url": "https://vyos.dev/T7217" + }, + { + "type": "WEB", + "url": "https://vyos.net/get/stream/#1.5-2025-Q1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8wg9-x5j6-rr5w/GHSA-8wg9-x5j6-rr5w.json b/advisories/unreviewed/2025/03/GHSA-8wg9-x5j6-rr5w/GHSA-8wg9-x5j6-rr5w.json new file mode 100644 index 00000000000..b215bdec43b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8wg9-x5j6-rr5w/GHSA-8wg9-x5j6-rr5w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wg9-x5j6-rr5w", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31607" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flomei Simple-Audioplayer allows Stored XSS. This issue affects Simple-Audioplayer: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31607" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-audioplayer/vulnerability/wordpress-simple-audioplayer-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8xj4-c9rx-w74q/GHSA-8xj4-c9rx-w74q.json b/advisories/unreviewed/2025/03/GHSA-8xj4-c9rx-w74q/GHSA-8xj4-c9rx-w74q.json new file mode 100644 index 00000000000..0cedb9d5bc9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8xj4-c9rx-w74q/GHSA-8xj4-c9rx-w74q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xj4-c9rx-w74q", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31559" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Caspio Bridge Custom Database Applications by Caspio allows DOM-Based XSS. This issue affects Custom Database Applications by Caspio: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31559" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-database-applications-by-caspio/vulnerability/wordpress-custom-database-applications-by-caspio-plugin-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-946p-25qj-wgq4/GHSA-946p-25qj-wgq4.json b/advisories/unreviewed/2025/03/GHSA-946p-25qj-wgq4/GHSA-946p-25qj-wgq4.json new file mode 100644 index 00000000000..da0a19efb0b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-946p-25qj-wgq4/GHSA-946p-25qj-wgq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-946p-25qj-wgq4", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31584" + ], + "details": "Missing Authorization vulnerability in elfsight Elfsight Testimonials Slider allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elfsight Testimonials Slider: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31584" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elfsight-testimonials-slider/vulnerability/wordpress-elfsight-testimonials-slider-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9772-pwrh-m696/GHSA-9772-pwrh-m696.json b/advisories/unreviewed/2025/03/GHSA-9772-pwrh-m696/GHSA-9772-pwrh-m696.json new file mode 100644 index 00000000000..3cc0b789492 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9772-pwrh-m696/GHSA-9772-pwrh-m696.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9772-pwrh-m696", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31567" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS. This issue affects Themesflat Addons For Elementor: from n/a through 2.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31567" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themesflat-addons-for-elementor/vulnerability/wordpress-themesflat-addons-for-elementor-plugin-2-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-97j3-x825-mg58/GHSA-97j3-x825-mg58.json b/advisories/unreviewed/2025/03/GHSA-97j3-x825-mg58/GHSA-97j3-x825-mg58.json new file mode 100644 index 00000000000..44ee8c7f664 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-97j3-x825-mg58/GHSA-97j3-x825-mg58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97j3-x825-mg58", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31596" + ], + "details": "Missing Authorization vulnerability in Chatwee Chat by Chatwee allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Chat by Chatwee: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31596" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chatwee/vulnerability/wordpress-chat-by-chatwee-plugin-2-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-98px-2578-cq7x/GHSA-98px-2578-cq7x.json b/advisories/unreviewed/2025/03/GHSA-98px-2578-cq7x/GHSA-98px-2578-cq7x.json new file mode 100644 index 00000000000..4df93333d8c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-98px-2578-cq7x/GHSA-98px-2578-cq7x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98px-2578-cq7x", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31600" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in designnbuy DesignO allows Cross Site Request Forgery. This issue affects DesignO: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31600" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/designo/vulnerability/wordpress-designo-plugin-2-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9fjh-h9rc-chv4/GHSA-9fjh-h9rc-chv4.json b/advisories/unreviewed/2025/03/GHSA-9fjh-h9rc-chv4/GHSA-9fjh-h9rc-chv4.json new file mode 100644 index 00000000000..cd35ee4cdb5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9fjh-h9rc-chv4/GHSA-9fjh-h9rc-chv4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fjh-h9rc-chv4", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-31629" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Allred Infusionsoft Web Form JavaScript allows Stored XSS. This issue affects Infusionsoft Web Form JavaScript: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31629" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/infusionsoft-web-form-javascript/vulnerability/wordpress-infusionsoft-web-form-javascript-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9p6m-j66g-84jh/GHSA-9p6m-j66g-84jh.json b/advisories/unreviewed/2025/03/GHSA-9p6m-j66g-84jh/GHSA-9p6m-j66g-84jh.json new file mode 100644 index 00000000000..4e61d6b0589 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9p6m-j66g-84jh/GHSA-9p6m-j66g-84jh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p6m-j66g-84jh", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31615" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in owenr88 Simple Contact Forms allows Stored XSS. This issue affects Simple Contact Forms: from n/a through 1.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31615" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-contact-forms/vulnerability/wordpress-simple-contact-forms-plugin-1-6-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9xg7-pgh6-596m/GHSA-9xg7-pgh6-596m.json b/advisories/unreviewed/2025/03/GHSA-9xg7-pgh6-596m/GHSA-9xg7-pgh6-596m.json new file mode 100644 index 00000000000..1ad4bd02f46 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9xg7-pgh6-596m/GHSA-9xg7-pgh6-596m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xg7-pgh6-596m", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31591" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in promoz73 Exit Popup Free allows Stored XSS. This issue affects Exit Popup Free: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31591" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/exit-popup-free/vulnerability/wordpress-exit-popup-free-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cgm2-63mv-58w4/GHSA-cgm2-63mv-58w4.json b/advisories/unreviewed/2025/03/GHSA-cgm2-63mv-58w4/GHSA-cgm2-63mv-58w4.json new file mode 100644 index 00000000000..1ae3e0b617f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cgm2-63mv-58w4/GHSA-cgm2-63mv-58w4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgm2-63mv-58w4", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31576" + ], + "details": "Missing Authorization vulnerability in Gagan Deep Singh PostmarkApp Email Integrator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PostmarkApp Email Integrator: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31576" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/postmarkapp-email-integrator/vulnerability/wordpress-postmarkapp-email-integrator-plugin-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-chjw-76rq-9c83/GHSA-chjw-76rq-9c83.json b/advisories/unreviewed/2025/03/GHSA-chjw-76rq-9c83/GHSA-chjw-76rq-9c83.json new file mode 100644 index 00000000000..8cdec1d5ad5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-chjw-76rq-9c83/GHSA-chjw-76rq-9c83.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chjw-76rq-9c83", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31557" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MiKa OSM – OpenStreetMap allows DOM-Based XSS. This issue affects OSM – OpenStreetMap: from n/a through 6.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31557" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/osm/vulnerability/wordpress-osm-openstreetmap-plugin-6-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cqjc-pfg6-24mx/GHSA-cqjc-pfg6-24mx.json b/advisories/unreviewed/2025/03/GHSA-cqjc-pfg6-24mx/GHSA-cqjc-pfg6-24mx.json index 5c1e2462c82..99287e29db9 100644 --- a/advisories/unreviewed/2025/03/GHSA-cqjc-pfg6-24mx/GHSA-cqjc-pfg6-24mx.json +++ b/advisories/unreviewed/2025/03/GHSA-cqjc-pfg6-24mx/GHSA-cqjc-pfg6-24mx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cqjc-pfg6-24mx", - "modified": "2025-03-19T21:30:52Z", + "modified": "2025-03-31T15:30:38Z", "published": "2025-03-18T21:32:01Z", "aliases": [ "CVE-2024-57151" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/jcxj/jcxj/blob/master/source/_posts/%E4%BF%A1%E5%91%BCoa%E5%AE%A1%E8%AE%A1.md" + }, + { + "type": "WEB", + "url": "https://github.com/l1uyi/cve-list/blob/main/cve-list/xinhu-CVE-2024-57171.md" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-crgj-f248-f5xj/GHSA-crgj-f248-f5xj.json b/advisories/unreviewed/2025/03/GHSA-crgj-f248-f5xj/GHSA-crgj-f248-f5xj.json new file mode 100644 index 00000000000..19ca9e939dc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-crgj-f248-f5xj/GHSA-crgj-f248-f5xj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crgj-f248-f5xj", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31604" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com allows Stored XSS. This issue affects Cal.com: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31604" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cal-com/vulnerability/wordpress-cal-com-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cv5f-6r7g-8q4w/GHSA-cv5f-6r7g-8q4w.json b/advisories/unreviewed/2025/03/GHSA-cv5f-6r7g-8q4w/GHSA-cv5f-6r7g-8q4w.json new file mode 100644 index 00000000000..db1d17164bd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cv5f-6r7g-8q4w/GHSA-cv5f-6r7g-8q4w.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv5f-6r7g-8q4w", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-29266" + ], + "details": "Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29266" + }, + { + "type": "WEB", + "url": "https://docs.unraid.net/unraid-os/release-notes/7.0.1" + }, + { + "type": "WEB", + "url": "https://edac.dev/security/CVE-2025-29266" + }, + { + "type": "WEB", + "url": "https://github.com/unraid/webgui" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-289" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f4hp-rmr7-r7v8/GHSA-f4hp-rmr7-r7v8.json b/advisories/unreviewed/2025/03/GHSA-f4hp-rmr7-r7v8/GHSA-f4hp-rmr7-r7v8.json new file mode 100644 index 00000000000..ad3dc9943e4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f4hp-rmr7-r7v8/GHSA-f4hp-rmr7-r7v8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4hp-rmr7-r7v8", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-2998" + ], + "details": "A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2998" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/149622" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/149622#issue-2935495265" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302047" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302047" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f8vv-47xg-39cp/GHSA-f8vv-47xg-39cp.json b/advisories/unreviewed/2025/03/GHSA-f8vv-47xg-39cp/GHSA-f8vv-47xg-39cp.json new file mode 100644 index 00000000000..14a23c68111 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f8vv-47xg-39cp/GHSA-f8vv-47xg-39cp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8vv-47xg-39cp", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31592" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo Melchiorre Send E-mail allows Stored XSS. This issue affects Send E-mail: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31592" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/send-e-mail/vulnerability/wordpress-send-e-mail-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g7qx-prg4-2frg/GHSA-g7qx-prg4-2frg.json b/advisories/unreviewed/2025/03/GHSA-g7qx-prg4-2frg/GHSA-g7qx-prg4-2frg.json new file mode 100644 index 00000000000..bc8a1c67edd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g7qx-prg4-2frg/GHSA-g7qx-prg4-2frg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7qx-prg4-2frg", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-31624" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LABCAT Processing Projects allows DOM-Based XSS. This issue affects Processing Projects: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31624" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/processing-projects/vulnerability/wordpress-processing-projects-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gfxg-3qf3-cv88/GHSA-gfxg-3qf3-cv88.json b/advisories/unreviewed/2025/03/GHSA-gfxg-3qf3-cv88/GHSA-gfxg-3qf3-cv88.json new file mode 100644 index 00000000000..ca083358db4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gfxg-3qf3-cv88/GHSA-gfxg-3qf3-cv88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfxg-3qf3-cv88", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31533" + ], + "details": "Missing Authorization vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Salesmate Add-On for Gravity Forms: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31533" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gf-salesmate-add-on/vulnerability/wordpress-salesmate-add-on-for-gravity-forms-plugin-2-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gm4q-xm9r-rfrp/GHSA-gm4q-xm9r-rfrp.json b/advisories/unreviewed/2025/03/GHSA-gm4q-xm9r-rfrp/GHSA-gm4q-xm9r-rfrp.json new file mode 100644 index 00000000000..e7190404b6b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gm4q-xm9r-rfrp/GHSA-gm4q-xm9r-rfrp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm4q-xm9r-rfrp", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31527" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Kishan WP Link Preview allows Server Side Request Forgery. This issue affects WP Link Preview: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31527" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-link-preview/vulnerability/wordpress-wp-link-preview-plugin-1-4-1-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gvv9-qq33-6gfv/GHSA-gvv9-qq33-6gfv.json b/advisories/unreviewed/2025/03/GHSA-gvv9-qq33-6gfv/GHSA-gvv9-qq33-6gfv.json new file mode 100644 index 00000000000..7424c49a101 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gvv9-qq33-6gfv/GHSA-gvv9-qq33-6gfv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvv9-qq33-6gfv", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31547" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aphotrax Uptime Robot Plugin for WordPress allows SQL Injection. This issue affects Uptime Robot Plugin for WordPress: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31547" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uptime-robot-monitor/vulnerability/wordpress-uptime-robot-plugin-for-wordpress-plugin-2-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gx79-fmcg-96m2/GHSA-gx79-fmcg-96m2.json b/advisories/unreviewed/2025/03/GHSA-gx79-fmcg-96m2/GHSA-gx79-fmcg-96m2.json new file mode 100644 index 00000000000..7490f26b624 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gx79-fmcg-96m2/GHSA-gx79-fmcg-96m2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx79-fmcg-96m2", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-22939" + ], + "details": "A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22939" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=Aic-QaSqjxc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hmpw-vvvc-x4mh/GHSA-hmpw-vvvc-x4mh.json b/advisories/unreviewed/2025/03/GHSA-hmpw-vvvc-x4mh/GHSA-hmpw-vvvc-x4mh.json new file mode 100644 index 00000000000..d8e61bb139b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hmpw-vvvc-x4mh/GHSA-hmpw-vvvc-x4mh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmpw-vvvc-x4mh", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-22937" + ], + "details": "An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22937" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hq66-qpx5-rcjm/GHSA-hq66-qpx5-rcjm.json b/advisories/unreviewed/2025/03/GHSA-hq66-qpx5-rcjm/GHSA-hq66-qpx5-rcjm.json new file mode 100644 index 00000000000..d0e48dd120f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hq66-qpx5-rcjm/GHSA-hq66-qpx5-rcjm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq66-qpx5-rcjm", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31569" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wp-buy wordpress related Posts with thumbnails allows Stored XSS. This issue affects wordpress related Posts with thumbnails: from n/a through 3.0.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31569" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/related-posts-list-grid-and-slider-all-in-one/vulnerability/wordpress-wordpress-related-posts-with-thumbnails-plugin-3-0-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hv45-666x-7h7j/GHSA-hv45-666x-7h7j.json b/advisories/unreviewed/2025/03/GHSA-hv45-666x-7h7j/GHSA-hv45-666x-7h7j.json new file mode 100644 index 00000000000..02e2de1c758 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hv45-666x-7h7j/GHSA-hv45-666x-7h7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv45-666x-7h7j", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31555" + ], + "details": "Missing Authorization vulnerability in ContentMX ContentMX Content Publisher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ContentMX Content Publisher: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31555" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contentmx-content-publisher/vulnerability/wordpress-contentmx-content-publisher-plugin-1-0-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j37g-ggjf-325g/GHSA-j37g-ggjf-325g.json b/advisories/unreviewed/2025/03/GHSA-j37g-ggjf-325g/GHSA-j37g-ggjf-325g.json new file mode 100644 index 00000000000..42ef9db07b5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j37g-ggjf-325g/GHSA-j37g-ggjf-325g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j37g-ggjf-325g", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31608" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reDim GmbH CookieHint WP allows Stored XSS. This issue affects CookieHint WP: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31608" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cookiehint-wp/vulnerability/wordpress-cookiehint-wp-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j37q-3xjr-5589/GHSA-j37q-3xjr-5589.json b/advisories/unreviewed/2025/03/GHSA-j37q-3xjr-5589/GHSA-j37q-3xjr-5589.json index 6130b29586e..dfe4b63badb 100644 --- a/advisories/unreviewed/2025/03/GHSA-j37q-3xjr-5589/GHSA-j37q-3xjr-5589.json +++ b/advisories/unreviewed/2025/03/GHSA-j37q-3xjr-5589/GHSA-j37q-3xjr-5589.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j37q-3xjr-5589", - "modified": "2025-03-30T00:30:23Z", + "modified": "2025-03-31T15:30:39Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-31160" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31160" }, + { + "type": "WEB", + "url": "https://blog.bismuth.sh/blog/bismuth-found-the-atop-bug" + }, { "type": "WEB", "url": "https://github.com/Atoptool/atop" diff --git a/advisories/unreviewed/2025/03/GHSA-j3jr-hg98-qw6f/GHSA-j3jr-hg98-qw6f.json b/advisories/unreviewed/2025/03/GHSA-j3jr-hg98-qw6f/GHSA-j3jr-hg98-qw6f.json new file mode 100644 index 00000000000..b415abe89dd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j3jr-hg98-qw6f/GHSA-j3jr-hg98-qw6f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3jr-hg98-qw6f", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31538" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Checklist allows Stored XSS. This issue affects Checklist: from n/a through 1.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31538" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/checklist/vulnerability/wordpress-checklist-plugin-1-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j43v-5872-49cm/GHSA-j43v-5872-49cm.json b/advisories/unreviewed/2025/03/GHSA-j43v-5872-49cm/GHSA-j43v-5872-49cm.json new file mode 100644 index 00000000000..d858b7eb44e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j43v-5872-49cm/GHSA-j43v-5872-49cm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j43v-5872-49cm", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31529" + ], + "details": "Missing Authorization vulnerability in Rashid Slider Path for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Slider Path for Elementor: from n/a through 3.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31529" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/slider-path/vulnerability/wordpress-slider-path-for-elementor-plugin-3-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jjcp-rrm8-4vx5/GHSA-jjcp-rrm8-4vx5.json b/advisories/unreviewed/2025/03/GHSA-jjcp-rrm8-4vx5/GHSA-jjcp-rrm8-4vx5.json index dce37b6f138..3f254f8b14e 100644 --- a/advisories/unreviewed/2025/03/GHSA-jjcp-rrm8-4vx5/GHSA-jjcp-rrm8-4vx5.json +++ b/advisories/unreviewed/2025/03/GHSA-jjcp-rrm8-4vx5/GHSA-jjcp-rrm8-4vx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jjcp-rrm8-4vx5", - "modified": "2025-03-31T12:30:44Z", + "modified": "2025-03-31T15:30:44Z", "published": "2025-03-31T12:30:44Z", "aliases": [ "CVE-2025-2990" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2990" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-AdvSetWrlGstset-1bc53a41781f8057a621c3def0a56069" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-AdvSetWrlGstset-1bc53a41781f8057a621c3def0a56069?pvs=4" diff --git a/advisories/unreviewed/2025/03/GHSA-jpmm-f834-xw7f/GHSA-jpmm-f834-xw7f.json b/advisories/unreviewed/2025/03/GHSA-jpmm-f834-xw7f/GHSA-jpmm-f834-xw7f.json new file mode 100644 index 00000000000..4a1f3047baf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jpmm-f834-xw7f/GHSA-jpmm-f834-xw7f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpmm-f834-xw7f", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31577" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in appointify Appointify allows Upload a Web Shell to a Web Server. This issue affects Appointify: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31577" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appointify/vulnerability/wordpress-appointify-plugin-1-0-8-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jvh2-r8jp-5mg5/GHSA-jvh2-r8jp-5mg5.json b/advisories/unreviewed/2025/03/GHSA-jvh2-r8jp-5mg5/GHSA-jvh2-r8jp-5mg5.json new file mode 100644 index 00000000000..932f24f4877 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jvh2-r8jp-5mg5/GHSA-jvh2-r8jp-5mg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvh2-r8jp-5mg5", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31606" + ], + "details": "Missing Authorization vulnerability in softpulseinfotech SP Blog Designer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SP Blog Designer: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31606" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sp-blog-designer/vulnerability/wordpress-sp-blog-designer-plugin-1-0-0-arbitrary-shortcode-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jw7p-3jmg-8h4h/GHSA-jw7p-3jmg-8h4h.json b/advisories/unreviewed/2025/03/GHSA-jw7p-3jmg-8h4h/GHSA-jw7p-3jmg-8h4h.json new file mode 100644 index 00000000000..33e2d2f124f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jw7p-3jmg-8h4h/GHSA-jw7p-3jmg-8h4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw7p-3jmg-8h4h", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31542" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wphocus My auctions allegro allows Blind SQL Injection. This issue affects My auctions allegro: from n/a through 3.6.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31542" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/my-auctions-allegro-free-edition/vulnerability/wordpress-my-auctions-allegro-plugin-3-6-20-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m348-74wh-fj2c/GHSA-m348-74wh-fj2c.json b/advisories/unreviewed/2025/03/GHSA-m348-74wh-fj2c/GHSA-m348-74wh-fj2c.json new file mode 100644 index 00000000000..850b3502909 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m348-74wh-fj2c/GHSA-m348-74wh-fj2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m348-74wh-fj2c", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31556" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IDX Broker IMPress for IDX Broker allows Stored XSS. This issue affects IMPress for IDX Broker: from n/a through 3.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31556" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/idx-broker-platinum/vulnerability/wordpress-impress-for-idx-broker-plugin-3-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mg72-wqw9-7xgq/GHSA-mg72-wqw9-7xgq.json b/advisories/unreviewed/2025/03/GHSA-mg72-wqw9-7xgq/GHSA-mg72-wqw9-7xgq.json new file mode 100644 index 00000000000..4c5a46f1ae1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mg72-wqw9-7xgq/GHSA-mg72-wqw9-7xgq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg72-wqw9-7xgq", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31589" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kibru Demeke Ethiopian Calendar allows Stored XSS. This issue affects Ethiopian Calendar: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31589" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ethiopian-calendar/vulnerability/wordpress-ethiopian-calendar-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mm7r-g6vw-pw46/GHSA-mm7r-g6vw-pw46.json b/advisories/unreviewed/2025/03/GHSA-mm7r-g6vw-pw46/GHSA-mm7r-g6vw-pw46.json new file mode 100644 index 00000000000..fe1e76471c5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mm7r-g6vw-pw46/GHSA-mm7r-g6vw-pw46.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm7r-g6vw-pw46", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31593" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OpenMenu OpenMenu allows Stored XSS. This issue affects OpenMenu: from n/a through 3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31593" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/open-menu/vulnerability/wordpress-openmenu-plugin-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mmvp-g6rj-vx7h/GHSA-mmvp-g6rj-vx7h.json b/advisories/unreviewed/2025/03/GHSA-mmvp-g6rj-vx7h/GHSA-mmvp-g6rj-vx7h.json new file mode 100644 index 00000000000..e5342fa9325 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mmvp-g6rj-vx7h/GHSA-mmvp-g6rj-vx7h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmvp-g6rj-vx7h", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31544" + ], + "details": "Missing Authorization vulnerability in WP Messiah Swiss Toolkit For WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Swiss Toolkit For WP: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31544" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/swiss-toolkit-for-wp/vulnerability/wordpress-swiss-toolkit-for-wp-plugin-1-3-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mw4p-73pj-gr2v/GHSA-mw4p-73pj-gr2v.json b/advisories/unreviewed/2025/03/GHSA-mw4p-73pj-gr2v/GHSA-mw4p-73pj-gr2v.json new file mode 100644 index 00000000000..e75cb78ec4c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mw4p-73pj-gr2v/GHSA-mw4p-73pj-gr2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw4p-73pj-gr2v", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31583" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Copy Media URL allows Stored XSS. This issue affects WP Copy Media URL: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31583" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-copy-media-url/vulnerability/wordpress-wp-copy-media-url-plugin-2-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mx57-8cw3-w58x/GHSA-mx57-8cw3-w58x.json b/advisories/unreviewed/2025/03/GHSA-mx57-8cw3-w58x/GHSA-mx57-8cw3-w58x.json new file mode 100644 index 00000000000..5406f4d0f40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mx57-8cw3-w58x/GHSA-mx57-8cw3-w58x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx57-8cw3-w58x", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31605" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WeblineIndia Welcome Popup allows Stored XSS. This issue affects Welcome Popup: from n/a through 1.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31605" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/welcome-popup/vulnerability/wordpress-welcome-popup-plugin-1-0-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p3mg-8v4v-xr9c/GHSA-p3mg-8v4v-xr9c.json b/advisories/unreviewed/2025/03/GHSA-p3mg-8v4v-xr9c/GHSA-p3mg-8v4v-xr9c.json new file mode 100644 index 00000000000..19fda2b6574 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p3mg-8v4v-xr9c/GHSA-p3mg-8v4v-xr9c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3mg-8v4v-xr9c", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31528" + ], + "details": "Missing Authorization vulnerability in wokamoto StaticPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects StaticPress: from n/a through 0.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31528" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/staticpress/vulnerability/wordpress-staticpress-plugin-0-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p7j9-ffwq-fqvg/GHSA-p7j9-ffwq-fqvg.json b/advisories/unreviewed/2025/03/GHSA-p7j9-ffwq-fqvg/GHSA-p7j9-ffwq-fqvg.json new file mode 100644 index 00000000000..3790a3e8b42 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p7j9-ffwq-fqvg/GHSA-p7j9-ffwq-fqvg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7j9-ffwq-fqvg", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31574" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftHopper Custom Content Scrollbar allows Stored XSS. This issue affects Custom Content Scrollbar: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31574" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-content-scrollbar/vulnerability/wordpress-custom-content-scrollbar-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pcfg-2qx6-cx4f/GHSA-pcfg-2qx6-cx4f.json b/advisories/unreviewed/2025/03/GHSA-pcfg-2qx6-cx4f/GHSA-pcfg-2qx6-cx4f.json new file mode 100644 index 00000000000..9f1d5f22882 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pcfg-2qx6-cx4f/GHSA-pcfg-2qx6-cx4f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcfg-2qx6-cx4f", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31616" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AdminGeekZ Varnish WordPress allows Cross Site Request Forgery. This issue affects Varnish WordPress: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31616" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/varnish-wp/vulnerability/wordpress-varnish-wordpress-plugin-1-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pvcv-83fh-wj6v/GHSA-pvcv-83fh-wj6v.json b/advisories/unreviewed/2025/03/GHSA-pvcv-83fh-wj6v/GHSA-pvcv-83fh-wj6v.json new file mode 100644 index 00000000000..4d09b8ba2c2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pvcv-83fh-wj6v/GHSA-pvcv-83fh-wj6v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvcv-83fh-wj6v", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31618" + ], + "details": "Missing Authorization vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Connector to CiviCRM with CiviMcRestFace: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31618" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/connector-civicrm-mcrestface/vulnerability/wordpress-connector-to-civicrm-with-civimcrestface-plugin-1-0-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q2v5-mh38-6c66/GHSA-q2v5-mh38-6c66.json b/advisories/unreviewed/2025/03/GHSA-q2v5-mh38-6c66/GHSA-q2v5-mh38-6c66.json new file mode 100644 index 00000000000..177c18836e4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q2v5-mh38-6c66/GHSA-q2v5-mh38-6c66.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2v5-mh38-6c66", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31530" + ], + "details": "Missing Authorization vulnerability in smackcoders Google SEO Pressor Snippet allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Google SEO Pressor Snippet: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31530" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-seo-author-snippets/vulnerability/wordpress-google-seo-pressor-snippet-plugin-2-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q429-5wf5-mwcw/GHSA-q429-5wf5-mwcw.json b/advisories/unreviewed/2025/03/GHSA-q429-5wf5-mwcw/GHSA-q429-5wf5-mwcw.json new file mode 100644 index 00000000000..614136ce7f9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q429-5wf5-mwcw/GHSA-q429-5wf5-mwcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q429-5wf5-mwcw", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31598" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Quantity Dynamic Pricing & Bulk Discounts for WooCommerce allows Stored XSS. This issue affects Quantity Dynamic Pricing & Bulk Discounts for WooCommerce: from n/a through 4.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31598" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wholesale-pricing-woocommerce/vulnerability/wordpress-quantity-dynamic-pricing-bulk-discounts-for-woocommerce-plugin-4-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q8r8-86rc-pp8v/GHSA-q8r8-86rc-pp8v.json b/advisories/unreviewed/2025/03/GHSA-q8r8-86rc-pp8v/GHSA-q8r8-86rc-pp8v.json new file mode 100644 index 00000000000..c56ab32ca5f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q8r8-86rc-pp8v/GHSA-q8r8-86rc-pp8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8r8-86rc-pp8v", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-31627" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media Library Assistant allows Stored XSS. This issue affects Media Library Assistant: from n/a through 3.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31627" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/media-library-assistant/vulnerability/wordpress-media-library-assistant-plugin-3-24-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qfr9-7c9v-fq5r/GHSA-qfr9-7c9v-fq5r.json b/advisories/unreviewed/2025/03/GHSA-qfr9-7c9v-fq5r/GHSA-qfr9-7c9v-fq5r.json new file mode 100644 index 00000000000..33c3c3fd098 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qfr9-7c9v-fq5r/GHSA-qfr9-7c9v-fq5r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfr9-7c9v-fq5r", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-22941" + ], + "details": "A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22941" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1levaZk5aC6g6a2zPW8xlOIVAu9MFYvAz/view" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qr2v-3fjr-52fc/GHSA-qr2v-3fjr-52fc.json b/advisories/unreviewed/2025/03/GHSA-qr2v-3fjr-52fc/GHSA-qr2v-3fjr-52fc.json new file mode 100644 index 00000000000..5e7ef0af42f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qr2v-3fjr-52fc/GHSA-qr2v-3fjr-52fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr2v-3fjr-52fc", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31609" + ], + "details": "Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPCargo Track & Trace: from n/a through 7.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31609" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpcargo/vulnerability/wordpress-wpcargo-track-trace-plugin-7-0-6-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qw8r-mf6v-692x/GHSA-qw8r-mf6v-692x.json b/advisories/unreviewed/2025/03/GHSA-qw8r-mf6v-692x/GHSA-qw8r-mf6v-692x.json new file mode 100644 index 00000000000..6a824a151c4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qw8r-mf6v-692x/GHSA-qw8r-mf6v-692x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw8r-mf6v-692x", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31610" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gingerplugins Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme allows Stored XSS. This issue affects Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31610" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gp-notification-bar/vulnerability/wordpress-notification-bar-sticky-notification-bar-sticky-welcome-bar-for-any-theme-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r3r3-hjgr-8x9f/GHSA-r3r3-hjgr-8x9f.json b/advisories/unreviewed/2025/03/GHSA-r3r3-hjgr-8x9f/GHSA-r3r3-hjgr-8x9f.json index cfb892b7443..3d50a56c745 100644 --- a/advisories/unreviewed/2025/03/GHSA-r3r3-hjgr-8x9f/GHSA-r3r3-hjgr-8x9f.json +++ b/advisories/unreviewed/2025/03/GHSA-r3r3-hjgr-8x9f/GHSA-r3r3-hjgr-8x9f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r3r3-hjgr-8x9f", - "modified": "2025-03-31T06:30:27Z", + "modified": "2025-03-31T15:30:43Z", "published": "2025-03-31T06:30:27Z", "aliases": [ "CVE-2025-0613" ], "details": "The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T06:15:29Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r9r3-5982-2cmx/GHSA-r9r3-5982-2cmx.json b/advisories/unreviewed/2025/03/GHSA-r9r3-5982-2cmx/GHSA-r9r3-5982-2cmx.json new file mode 100644 index 00000000000..a399f7ef7ef --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r9r3-5982-2cmx/GHSA-r9r3-5982-2cmx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9r3-5982-2cmx", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31590" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Denra.com WP Date and Time Shortcode allows Stored XSS. This issue affects WP Date and Time Shortcode: from n/a through 2.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31590" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-date-and-time-shortcode/vulnerability/wordpress-wp-date-and-time-shortcode-plugin-2-6-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rmq9-ph99-fffg/GHSA-rmq9-ph99-fffg.json b/advisories/unreviewed/2025/03/GHSA-rmq9-ph99-fffg/GHSA-rmq9-ph99-fffg.json new file mode 100644 index 00000000000..555720204c9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rmq9-ph99-fffg/GHSA-rmq9-ph99-fffg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmq9-ph99-fffg", + "modified": "2025-03-31T15:30:47Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31613" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Aboobacker. AB Google Map Travel allows Cross Site Request Forgery. This issue affects AB Google Map Travel : from n/a through 4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31613" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ab-google-map-travel/vulnerability/wordpress-ab-google-map-travel-plugin-4-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rrmf-rvhw-rf47/GHSA-rrmf-rvhw-rf47.json b/advisories/unreviewed/2025/03/GHSA-rrmf-rvhw-rf47/GHSA-rrmf-rvhw-rf47.json new file mode 100644 index 00000000000..9739c178869 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rrmf-rvhw-rf47/GHSA-rrmf-rvhw-rf47.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrmf-rvhw-rf47", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-3000" + ], + "details": "A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3000" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/149623" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/149623#issue-2935703015" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302049" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302049" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524197" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v2gc-j689-433p/GHSA-v2gc-j689-433p.json b/advisories/unreviewed/2025/03/GHSA-v2gc-j689-433p/GHSA-v2gc-j689-433p.json new file mode 100644 index 00000000000..e15f008c13e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v2gc-j689-433p/GHSA-v2gc-j689-433p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2gc-j689-433p", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31575" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vasilis Triantafyllou Flag Icons allows Stored XSS. This issue affects Flag Icons: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31575" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/language-icons-flags-switcher/vulnerability/wordpress-flag-icons-plugin-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v5p7-3387-gpmg/GHSA-v5p7-3387-gpmg.json b/advisories/unreviewed/2025/03/GHSA-v5p7-3387-gpmg/GHSA-v5p7-3387-gpmg.json index 2bc3e724abd..619dd3f343d 100644 --- a/advisories/unreviewed/2025/03/GHSA-v5p7-3387-gpmg/GHSA-v5p7-3387-gpmg.json +++ b/advisories/unreviewed/2025/03/GHSA-v5p7-3387-gpmg/GHSA-v5p7-3387-gpmg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v5p7-3387-gpmg", - "modified": "2025-03-31T09:30:33Z", + "modified": "2025-03-31T15:30:43Z", "published": "2025-03-31T09:30:33Z", "aliases": [ "CVE-2025-2402" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2402" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-v5p7-3387-gpmg" + }, { "type": "WEB", "url": "https://www.knime.com/security/advisories#CVE-2025-2402" diff --git a/advisories/unreviewed/2025/03/GHSA-v655-qj86-qg6x/GHSA-v655-qj86-qg6x.json b/advisories/unreviewed/2025/03/GHSA-v655-qj86-qg6x/GHSA-v655-qj86-qg6x.json new file mode 100644 index 00000000000..f3ab9700da8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v655-qj86-qg6x/GHSA-v655-qj86-qg6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v655-qj86-qg6x", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31543" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twice Commerce Twice Commerce allows DOM-Based XSS. This issue affects Twice Commerce: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31543" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/embed-rentle/vulnerability/wordpress-twice-commerce-plugin-1-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v82v-ch87-hj9j/GHSA-v82v-ch87-hj9j.json b/advisories/unreviewed/2025/03/GHSA-v82v-ch87-hj9j/GHSA-v82v-ch87-hj9j.json new file mode 100644 index 00000000000..cae10f7b3ed --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v82v-ch87-hj9j/GHSA-v82v-ch87-hj9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v82v-ch87-hj9j", + "modified": "2025-03-31T15:30:46Z", + "published": "2025-03-31T15:30:46Z", + "aliases": [ + "CVE-2025-31597" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in crazycric Ultimate Live Cricket WordPress Lite allows Stored XSS. This issue affects Ultimate Live Cricket WordPress Lite: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31597" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-live-cricket-lite/vulnerability/wordpress-ultimate-live-cricket-wordpress-lite-plugin-1-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vgrw-7cvw-pwgx/GHSA-vgrw-7cvw-pwgx.json b/advisories/unreviewed/2025/03/GHSA-vgrw-7cvw-pwgx/GHSA-vgrw-7cvw-pwgx.json new file mode 100644 index 00000000000..6b5544a1b27 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vgrw-7cvw-pwgx/GHSA-vgrw-7cvw-pwgx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgrw-7cvw-pwgx", + "modified": "2025-03-31T15:30:49Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2025-2999" + ], + "details": "A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2999" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/149622" + }, + { + "type": "WEB", + "url": "https://github.com/pytorch/pytorch/issues/149622#issue-2935495265" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302048" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302048" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524198" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w39w-vrpr-4vxx/GHSA-w39w-vrpr-4vxx.json b/advisories/unreviewed/2025/03/GHSA-w39w-vrpr-4vxx/GHSA-w39w-vrpr-4vxx.json new file mode 100644 index 00000000000..4f770e4366e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w39w-vrpr-4vxx/GHSA-w39w-vrpr-4vxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w39w-vrpr-4vxx", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2025-31623" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in richtexteditor Rich Text Editor allows Stored XSS. This issue affects Rich Text Editor: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31623" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/richtexteditor/vulnerability/wordpress-rich-text-editor-plugin-1-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wgw2-48jp-77f3/GHSA-wgw2-48jp-77f3.json b/advisories/unreviewed/2025/03/GHSA-wgw2-48jp-77f3/GHSA-wgw2-48jp-77f3.json new file mode 100644 index 00000000000..6f7baf961d1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wgw2-48jp-77f3/GHSA-wgw2-48jp-77f3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgw2-48jp-77f3", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:48Z", + "aliases": [ + "CVE-2024-12021" + ], + "details": "Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interfaces. The impact of exploitation may result in the compromise of local accounts managed by the Coverity platform as well as other standard impacts resulting from cross-site scripting.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12021" + }, + { + "type": "WEB", + "url": "https://community.blackduck.com/s/article/Black-Duck-Product-Security-Advisory-CVE-2024-12021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wq39-xrp6-m552/GHSA-wq39-xrp6-m552.json b/advisories/unreviewed/2025/03/GHSA-wq39-xrp6-m552/GHSA-wq39-xrp6-m552.json new file mode 100644 index 00000000000..ccd5dd20a7d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wq39-xrp6-m552/GHSA-wq39-xrp6-m552.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq39-xrp6-m552", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:45Z", + "aliases": [ + "CVE-2025-31570" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wp-buy Related Posts Widget with Thumbnails allows Stored XSS. This issue affects Related Posts Widget with Thumbnails: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31570" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-css3-related-posts-widget/vulnerability/wordpress-related-posts-widget-with-thumbnails-plugin-1-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wrxc-qw43-c96x/GHSA-wrxc-qw43-c96x.json b/advisories/unreviewed/2025/03/GHSA-wrxc-qw43-c96x/GHSA-wrxc-qw43-c96x.json new file mode 100644 index 00000000000..5e484c0424e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wrxc-qw43-c96x/GHSA-wrxc-qw43-c96x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrxc-qw43-c96x", + "modified": "2025-03-31T15:30:48Z", + "published": "2025-03-31T15:30:47Z", + "aliases": [ + "CVE-2023-0881" + ], + "details": "Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0881" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/ubuntu/+source/linux-bluefield/+bug/2006397" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x2jj-vrxq-66gv/GHSA-x2jj-vrxq-66gv.json b/advisories/unreviewed/2025/03/GHSA-x2jj-vrxq-66gv/GHSA-x2jj-vrxq-66gv.json new file mode 100644 index 00000000000..11349c725fe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x2jj-vrxq-66gv/GHSA-x2jj-vrxq-66gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2jj-vrxq-66gv", + "modified": "2025-03-31T15:30:45Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2025-31540" + ], + "details": "Missing Authorization vulnerability in acmemediakits ACME Divi Modules allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ACME Divi Modules: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31540" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/acme-divi-modules/vulnerability/wordpress-acme-divi-modules-plugin-1-3-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xf9x-cj4h-4674/GHSA-xf9x-cj4h-4674.json b/advisories/unreviewed/2025/03/GHSA-xf9x-cj4h-4674/GHSA-xf9x-cj4h-4674.json index 4ce1a84e733..59a65c8af54 100644 --- a/advisories/unreviewed/2025/03/GHSA-xf9x-cj4h-4674/GHSA-xf9x-cj4h-4674.json +++ b/advisories/unreviewed/2025/03/GHSA-xf9x-cj4h-4674/GHSA-xf9x-cj4h-4674.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xf9x-cj4h-4674", - "modified": "2025-03-31T12:30:44Z", + "modified": "2025-03-31T15:30:44Z", "published": "2025-03-31T12:30:44Z", "aliases": [ "CVE-2025-2989" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2989" }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-AdvSetWrl-1bc53a41781f8011b0b4d3d65cacc82f" + }, { "type": "WEB", "url": "https://lavender-bicycle-a5a.notion.site/Tenda-FH1202-AdvSetWrl-1bc53a41781f8011b0b4d3d65cacc82f?pvs=4" diff --git a/advisories/unreviewed/2025/03/GHSA-xjqw-3pxc-hgh8/GHSA-xjqw-3pxc-hgh8.json b/advisories/unreviewed/2025/03/GHSA-xjqw-3pxc-hgh8/GHSA-xjqw-3pxc-hgh8.json new file mode 100644 index 00000000000..f2e2afd4f58 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xjqw-3pxc-hgh8/GHSA-xjqw-3pxc-hgh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjqw-3pxc-hgh8", + "modified": "2025-03-31T15:30:44Z", + "published": "2025-03-31T15:30:44Z", + "aliases": [ + "CVE-2024-55093" + ], + "details": "phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55093" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/d0caaeba885364fd0521f094511c5d7b11f9da8f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-31T13:15:42Z" + } +} \ No newline at end of file